6.5
CVSSv2

CVE-2008-2521

Published: 03/06/2008 Updated: 29/09/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in members.php in YABSoft Mega File Hosting Script (aka MFH or MFHS) 1.2 allows remote authenticated users to execute arbitrary SQL commands via the fid parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

yabsoft mega file hosting script 1.2

Exploits

######################################## Script: Mega File Hosting script ######################################## Type: SQL Injection ######################################## 1923TURKORG TURKiSHWARRiORR Step 1: Register an account Step 2: login and go to /membersphp?folders=1 Step 3: Create a folder with any name Exploitation options: ...